60a715a0dd79873d2d2607eab8fdfaf0ffd2e7d3 |
|
09-Feb-2018 |
Hristo Venev <hristo@venev.name> |
providers: Move hostid from ipa to sdap, v2
In the ldap provider, all option names are renamed to ldap_host_*. In
the ipa provider the names haven't been changed.
Host lookups for both ipa and ldap are handled in the ldap provider.
sss_ssh_knownhostsproxy works but hostgroups are still only available
in the ipa provider.
I've also added some documentation for the ldap provider.
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com> |
f651d895bcb3fe6597fbf382e5b2955acddfe0c0 |
|
03-Jan-2018 |
Jakub Hrozek <jhrozek@redhat.com> |
MAN: Describe the constrains of ipa_server_mode better in the man page
Amends the sssd-ipa man page so that we explicitly say that:
* SSSD needs to be pointed at the IPA server itself
* SSSD currently needs to print fully qualified names for users for
trusted domains.
Resolves:
https://pagure.io/SSSD/sssd/issue/3484
Reviewed-by: Justin Stephenson <jstephen@redhat.com>
Reviewed-by: Fabiano Fidêncio <fidencio@redhat.com> |
89ed594e8800fdb288248006e8867a077a57bc6f |
|
21-Dec-2017 |
Jakub Hrozek <jhrozek@redhat.com> |
MAN: Document that auth and access IPA and AD providers rely on id_provider being set to the same type
The IPA and AD auth and access providers rely (often for performance
reasons) on certain properties that are set during the user or
group resolution with the same provider type.
However, there are users who wish to combine different provider types,
typically to use identities from local UNIX files but authenticate
against a remote server. We should discourage that in our documentation
(but at the same time, I think flat our failing would be too harsh..)
Resolves:
https://pagure.io/SSSD/sssd/issue/3547
Reviewed-by: Justin Stephenson <jstephen@redhat.com> |
fdefac9c4a5c9f2dcc8748ccb736e9a6910c2365 |
|
13-Sep-2017 |
AmitKumar <amitkuma@redhat.com> |
MAN: Improve ipa_hostname description
The description of ipa_hostname config option doesn't mention it must be
fully-qualified, although when using a non-fully qualified name IPA
server may behave weirdly. Thus, let's add this info the the man page.
Related: https://pagure.io/SSSD/sssd/issue/1946
Reviewed-by: Fabiano Fidêncio <fidencio@redhat.com>
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com> |
4a311702045b065a97a0c0fc0ccc7a1fc84b38cf |
|
28-Aug-2017 |
Fabiano Fidêncio <fidencio@redhat.com> |
DESKPROFILE: Add ipa_deskprofile_request_interval
This option has been added to avoid contacting the Data Provider when no
rules were found in the previous request.
By adding this configurable option we avoid contacting the Data Provider
too often in the case described above and also when the server doesn't
support Desktop Profile's integration.
Resolves: https://pagure.io/SSSD/sssd/issue/3482
Signed-off-by: Fabiano Fidêncio <fidencio@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com> |
f982039c75ec064894deb676ae53ee57de868590 |
|
28-Aug-2017 |
Fabiano Fidêncio <fidencio@redhat.com> |
DESKPROFILE: Introduce the new IPA session provider
In order to provide FleetCommander[0] integration, a session provider
has been introduced for IPA. The design of this feature and more
technical details can be found at [1] and [2], which are the design
pages of both freeIPA and SSSD parts.
As there's no way to test freeIPA integration with our upstream tests,
no test has been provided yet.
Is also worth to mention that the name "deskprofile" has been chosen
instead of "fleetcmd" in order to match with the freeIPA plugin. It
means that, for consistence, all source files, directories created,
options added, functions prefixes and so on are following the choice
accordingly.
[0]: https://wiki.gnome.org/Projects/FleetCommander
[1]: https://github.com/abbra/freeipa-desktop-profile/blob/master/plugin/Feature.mediawiki
[2]: https://docs.pagure.org/SSSD.sssd/design_pages/fleet_commander_integration.html
Resolves:
https://pagure.io/SSSD/sssd/issue/2995
Signed-off-by: Fabiano Fidêncio <fidencio@redhat.com>
Reviewed-by: Pavel Březina <pbrezina@redhat.com>
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com> |
2bd5bb45189c4916c09b5c8a13ebe509f8a0987a |
|
18-Jul-2017 |
AmitKumar <amitkuma@redhat.com> |
MAN: Updating option ipa_server_mode in man sssd-ipa
Changes done for section ipa_server_mode since description of section was bit vague. Text is re-phrased for better understanding.
Resolves: https://pagure.io/SSSD/sssd/issue/3404
Reviewed-by: Fabiano Fidêncio <fidencio@redhat.com> |
352f4832324839d358235de1236090b1fd4ddc0f |
|
28-Apr-2017 |
René Genz <liebundartig@freenet.de> |
Use correct spelling of override
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com> |
5424b90e870cf2b9d379df185cb6893c7f8b040c |
|
07-Mar-2017 |
Justin Stephenson <jstephen@redhat.com> |
MAN: Add dyndns_auth option
Add the dyndns_auth option into the AD or IPA provider man pages for
more configuration information of nsupdate behavior.
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com> |
8caf7ba5005b3be5447311713ad2b58169f9d32f |
|
15-Nov-2016 |
Justin Stephenson <jstephen@redhat.com> |
MAN: Document different defaults for IPA provider
Update man pages for any IPA provider config options that differ from
ldap/krb5 provider back-end defaults
Resolves:
https://fedorahosted.org/sssd/ticket/3214
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com>
Reviewed-by: Lukáš Slebodník <lslebodn@redhat.com> |
b7d7bdf24a6b286391175f1f9cc392faacb1ab8a |
|
28-Apr-2016 |
Jakub Hrozek <jhrozek@redhat.com> |
MAN: Drop the reference to IPAv2 in the man page
As suggested by Rob in
https://fedorahosted.org/sssd/ticket/1907#comment:2
Reviewed-by: Lukáš Slebodník <lslebodn@redhat.com> |
7c3cc1ee2914bc7b38a992c1af254fc76af5a1ad |
|
14-Aug-2015 |
Pavel Reichl <preichl@redhat.com> |
DYNDNS: Don't use server cmd in nsupdate by default
nsupdate command `server` should not be used for the first attempt
to udpate DNS. It should be used only in subsequent attempts after the
first attempt failed.
Resolves:
https://fedorahosted.org/sssd/ticket/2495
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com> |
8145ab51b05aa86b2f1a21b49383f55e50b0a2e3 |
|
14-Aug-2015 |
Jakub Hrozek <jhrozek@redhat.com> |
DYNDNS: Add a new option dyndns_server
Some environments use a different DNS server than identity server. For
these environments, it would be useful to be able to override the DNS
server used to perform DNS updates.
This patch adds a new option dyndns_server that, if set, would be used
to hardcode a DNS server address into the nsupdate message.
Reviewed-by: Pavel Reichl <preichl@redhat.com> |
0a26e92fb2a4dd9704a0578f90241997e2aed269 |
|
24-Jul-2015 |
Pavel Reichl <preichl@redhat.com> |
DYNDNS: special value '*' for dyndns_iface option
Option dyndns_iface has now special value '*' which implies that IPs
from add interfaces should be sent during DDNS update. |
038b9ba28a618e3e553803da632116a040b94034 |
|
24-Jul-2015 |
Pavel Reichl <preichl@redhat.com> |
DYNDNS: support mult. interfaces for dyndns_iface opt
Resolves:
https://fedorahosted.org/sssd/ticket/2549 |
6dff95bdfe437afc0b62b5270d0d84140981c786 |
|
24-Mar-2015 |
Jakub Hrozek <jhrozek@redhat.com> |
IPA: Remove the ipa_hbac_treat_deny_as option
https://fedorahosted.org/sssd/ticket/2603
Since deny rules are no longer supported on the server, the client
should no longer support them either. Remove the option.
Reviewed-by: Pavel Březina <pbrezina@redhat.com> |
702176303382b5a385e90fe68ad2c32bd708ebf1 |
|
15-Jan-2015 |
Pavel Reichl <preichl@redhat.com> |
MAN: dyndns_iface supports only one interface
Resolves:
https://fedorahosted.org/sssd/ticket/2548
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com> |
ecf9e7a870945ecfba8eb751d344de3601de9424 |
|
14-Jan-2015 |
Lukas Slebodnik <lslebodn@redhat.com> |
MAN: Remove indentation in element programlistening
The indentation is automatically in resulting man page. It isn't necessary to
add spaces and moreover it can cause unreadable page asi in case of ad_gpo_map
examples.
Reviewed-by: Roland Mainz <rmainz@redhat.com> |
4fa184e2c60b377fd71e0115a618bd68dc73627d |
|
25-Nov-2014 |
Sumit Bose <sbose@redhat.com> |
AD/IPA: add krb5_confd_path configuration option
With this new parameter the directory where Kerberos configuration
snippets are created can be specified.
Fixes https://fedorahosted.org/sssd/ticket/2473
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com> |
ab355eced46b5f488ed62a79a7f2e5ac2b6a574c |
|
05-Nov-2014 |
Sumit Bose <sbose@redhat.com> |
Views: apply user SSH public key override
With this patch the SSH public key override attribute is read from the
FreeIPA server and saved in the cache with the other override data.
Since it is possible to have multiple public SSH keys this override
value does not replace any other data but will be added to existing
values.
Fixes https://fedorahosted.org/sssd/ticket/2454
Reviewed-by: Jakub Hrozek <jhrozek@redhat.com> |
08ab0d4ede41a1749e0bc26f78a37a4d10c20db8 |
|
16-Oct-2014 |
Sumit Bose <sbose@redhat.com> |
IPA: add view support and get view name
Related to https://fedorahosted.org/sssd/ticket/2375
Reviewed-by: Pavel Březina <pbrezina@redhat.com> |
4a494e7d686d97ebb3260fa75d10466575d01e69 |
|
17-Feb-2014 |
Jakub Hrozek <jhrozek@redhat.com> |
MAN: Clarify the new krb5_use_fast IPA default |
65a8e6e655c22027d3e02ea697972111f2a33e33 |
|
11-Oct-2013 |
Jakub Hrozek <jhrozek@redhat.com> |
MAN: Fix refsect-id
The refsect id was copied from sssd.conf(5) and was wrong. Fixing the
refsect might help us if we ever generate other formats from XML and
certainly wouldn't hurt. |
7b58d637c20f87e1e49ffc1d49a4de8b25ef06bb |
|
20-Sep-2013 |
Jakub Hrozek <jhrozek@redhat.com> |
MAN: Fix provider man page subtitle |
caf576da562bf7bd30e74ad921c1212ec7d230bc |
|
13-Sep-2013 |
Ondrej Kos <okos@redhat.com> |
IPA: Deprecate ipa_hbac_support_srchost option
This option got already deprecated on the ipa server side.
Option is undocumented and warning is printed both to the sssd log files
and syslog.
Resolves:
https://fedorahosted.org/sssd/ticket/1918 |
777b638893289fa0b8743415ff1945c6468bd8b0 |
|
13-Sep-2013 |
Ondrej Kos <okos@redhat.com> |
MAN: Remove IPA specific LDAP settings
Resolves:
https://fedorahosted.org/sssd/ticket/1187 |
898c4f965aeea2aa029ad56b9e9f48abce17a582 |
|
25-Jul-2013 |
Yuri Chornoivan <yurchor@ukr.net> |
Fix two minor typos |
0249e8d37920f59fd70bdafa4f6706a05ae523c1 |
|
28-Jun-2013 |
Jakub Hrozek <jhrozek@redhat.com> |
IPA: Add a server mode option
https://fedorahosted.org/sssd/ticket/1993
SSSD needs to know that it is running on an IPA server and should not
look up trusted users and groups with the help of the extdom plugin
but do the lookups on its own. For this a new boolean configuration
option, is introduced which defaults to false but is set to true during
ipa-server-install or during updates of the FreeIPA server if it is not
already set. |
593c4a91596640eafe798e8aac700d0f3ce7ba37 |
|
30-May-2013 |
Ondrej Kos <okos@redhat.com> |
MAN: state default dyndns interface
https://fedorahosted.org/sssd/ticket/1924 |
105c7a324c3ee2930b23513ae73aeddce0d8c347 |
|
14-May-2013 |
Jakub Hrozek <jhrozek@redhat.com> |
man: Note that IPA updates are secured with GSS-TSIG |
41bfa213a0994cebcef5f69fd2c353136c803ae4 |
|
06-May-2013 |
Yuri Chornoivan <yurchor@ukr.net> |
Fix minor typos |
e45b81abe0aafa8a04bd64ac31a2fac63ce675b7 |
|
03-May-2013 |
Jakub Hrozek <jhrozek@redhat.com> |
dyndns: new option dyndns_force_tcp
https://fedorahosted.org/sssd/ticket/1831
Adds a new option that can be used to force nsupdate to only use TCP to
communicate with the DNS server. |
38ebc764eeb7693e0c4f0894d6687e54fbba871b |
|
03-May-2013 |
Jakub Hrozek <jhrozek@redhat.com> |
dyndns: New option dyndns_update_ptr
https://fedorahosted.org/sssd/ticket/1832
While some servers, such as FreeIPA allow the PTR record to be
synchronized when the forward record is updated, other servers,
including Active Directory, require that the PTR record is synchronized
manually.
This patch adds a new option, dyndns_update_ptr that automatically
generates appropriate DNS update message for updating the reverse zone.
This option is off by default in the IPA provider.
Also renames be_nsupdate_create_msg to be_nsupdate_create_fwd_msg |
5a4239490c7fb7d732180a9d40f27f0247c56631 |
|
03-May-2013 |
Jakub Hrozek <jhrozek@redhat.com> |
dyndns: new option dyndns_refresh_interval
This new options adds the possibility of updating the DNS entries
periodically regardless if they have changed or not. This feature
will be useful mainly in AD environments where the Windows clients
periodically update their DNS records. |
04868f1573f4b26ef34610b6d7069172f93bd8ab |
|
03-May-2013 |
Jakub Hrozek <jhrozek@redhat.com> |
Convert IPA-specific options to be back-end agnostic
This patch introduces new options for dynamic DNS updates that are not
specific to any back end. The current ipa dyndns options are still
usable, just with a deprecation warning. |
88275cccddf39892e01682b39b02292eb74729bd |
|
10-Apr-2013 |
Pavel Březina <pbrezina@redhat.com> |
DNS sites support - add IPA SRV plugin
https://fedorahosted.org/sssd/ticket/1032 |
3bfb5e2c7fb452a6a2809829213148870d49d4e0 |
|
03-Apr-2013 |
Yuri Chornoivan <yurchor@ukr.net> |
Fix typos in man pages |
ba4378f49914e65a7d687a872d9b938173841154 |
|
19-Mar-2013 |
Michal Zidek <mzidek@redhat.com> |
Make the SELinux refresh time configurable.
Option ipa_selinux_refresh is added to basic ipa options. |
5063dcc5ab685dce325b13b9c1e93cee2a673e60 |
|
14-Nov-2012 |
Sumit Bose <sbose@redhat.com> |
Run IPA subdomain provider if IPA ID provider is configured
To make configuration easier the IPA subdomain provider should be always
loaded if the IPA ID provider is configured and the subdomain provider
is not explicitly disabled. But to avoid the overhead of regular
subdomain requests in setups where no subdomains are used the IPA
subdomain provider should behave differently if configured explicit or
implicit.
If the IPA subdomain provider is configured explicitly, i.e.
'subdomains_provider = ipa' can be found in the domain section of
sssd.conf subdomain request are always send to the server if needed.
If it is configured implicitly and a request to the server fails
with an indication that the server currently does not support subdomains
at all, e.g. is not configured to handle trust relationships, a new
request will be only send to the server after a long timeout or after
a going-online event.
To be able to make this distinction this patch save the configuration
status to the subdomain context.
Fixes https://fedorahosted.org/sssd/ticket/1613 |
778491bebee536a196afc29b0d9953843a5374b2 |
|
14-Nov-2012 |
Sumit Bose <sbose@redhat.com> |
Always start PAC responder if IPA ID provider is configured
Since the PAC responder is used during the authentication of users from
trusted realms it is started automatically if the IPA ID provider is
configured for a domain to simplify the configuration.
Fixes https://fedorahosted.org/sssd/ticket/1613 |
4fb12db7504920d12ea7db71f312334c877bff7c |
|
16-Oct-2012 |
James Hogarth <james.hogarth@gmail.com> |
Make TTL configurable for dynamic dns updates |
002dfe55ef258b73ca85eb813b1a156789b7702a |
|
05-Oct-2012 |
Jakub Hrozek <jhrozek@redhat.com> |
man: Note that automounter must be restarted to re-read the master map
https://fedorahosted.org/sssd/ticket/1563 |
c0d9babd59c81c12ca182ab3a72176d4fae494a4 |
|
03-Aug-2012 |
Yuri Chornoivan <yurchor@ukr.net> |
Fix various typos in documentation. |
46118ee53dc0d25e449cd7e37e624a4c62b78ee2 |
|
01-Aug-2012 |
Jan Zeleny <jzeleny@redhat.com> |
Primary server support: new option in IPA provider
This patch adds support for new config option ipa_backup_server. The
description of this option's functionality is included in man page in
one of previous patches. |
544525ee1fc54d744c08465066e2b4a521f78224 |
|
06-Jul-2012 |
Stephen Gallagher <sgallagh@redhat.com> |
MAN: Unify "SEE ALSO" sections |
84c611c1b7c04cc7735ab54d4e5f48284b79e6fb |
|
10-Jun-2012 |
Jan Zeleny <jzeleny@redhat.com> |
IPA subdomains - ask for information about master domain
The query is performed only if there is missing information in the
cache. That means this should be done only once after restart when cache
doesn't exist. All subsequent requests for subdomains won't include the
request for master domain. |
81165faf5d951aca69f410713730c26ff048ec44 |
|
24-Apr-2012 |
Sumit Bose <sbose@redhat.com> |
IPA: Add get-domains target |
620033ce66f4827be9d508c77483fab0270d9869 |
|
07-Feb-2012 |
Jakub Hrozek <jhrozek@redhat.com> |
AUTOFS: IPA provider |
1a7d1977037864e52858058777af8ff8401547dd |
|
07-Feb-2012 |
Jan Cholasta <jcholast@redhat.com> |
IPA: Add host info handler |
28eff88014a299041564e829b8b6e0f159baa24d |
|
06-Feb-2012 |
Jan Zeleny <jzeleny@redhat.com> |
Man pages for the session target and SELinux user maps fetching |
2be3039b8fc8ec07a323d15060123366da786dc5 |
|
17-Jan-2012 |
Stephen Gallagher <sgallagh@redhat.com> |
IPA: Detect nsupdate support for the realm directive
For older platforms, do not add the 'realm' line in
the update message |
e4ae14ff4b2b37ce2e356a77c687e33e6d5a2b33 |
|
14-Jan-2012 |
Jan Zeleny <jzeleny@redhat.com> |
Add info about ipa_host_search_base to man page
Also add comment that setting ipa_hbac_support_srchost to False disables
search filters given in ipa_host_search_base |
6fb75e297bf7fc83e3db1f5ae8560624656ef319 |
|
29-Nov-2011 |
Jan Zeleny <jzeleny@redhat.com> |
Add ipa_hbac_support_srchost option to IPA provider
don't fetch all host groups if this option is false
https://fedorahosted.org/sssd/ticket/1078 |
544de543ee88961272e9b9c5baa2c0d296162965 |
|
23-Nov-2011 |
Jan Zeleny <jzeleny@redhat.com> |
Added and modified options for IPA netgroups |
f0a34aeb49f3efd4c94b5afcb22671aac3098ddb |
|
10-Nov-2011 |
Yuri Chornoivan <yurchor@ukr.net> |
Fix typos in manual pages |
7dfc7617085c403d30debe9f08d4c9bcca322744 |
|
02-Nov-2011 |
Jan Zeleny <jzeleny@redhat.com> |
Add support to request canonicalization on krb AS requests
https://fedorahosted.org/sssd/ticket/957 |
83ac515cf3b9d278f8df3bbd08d6ae53b5666120 |
|
13-Oct-2011 |
Jan Zeleny <jzeleny@redhat.com> |
man page fix (lists are comma-separated)
https://fedorahosted.org/sssd/ticket/1024 |
98fc4cbc838615a88b9725a13ab7491e89cbac32 |
|
08-Jul-2011 |
Stephen Gallagher <sgallagh@redhat.com> |
Add ipa_hbac_treat_deny_as option
By default, we will treat the presence of any DENY rule as denying
all users. This option will allow the admin to explicitly ignore
DENY rules during a transitional period. |
1360b4f4d6e948023daeda8787f575e7f8117444 |
|
08-Jul-2011 |
Stephen Gallagher <sgallagh@redhat.com> |
Add ipa_hbac_refresh option
This option describes the time between refreshes of the HBAC rules
on the IPA server. |
073e71701dc28e21aaa1750d8b456ac699b8dda8 |
|
28-Feb-2011 |
Jakub Hrozek <jhrozek@redhat.com> |
Use realm for basedn instead of IPA domain
https://fedorahosted.org/sssd/ticket/807 |
56789cfa13f85071f5fb37575fa1f1071f587efc |
|
19-Jan-2011 |
Sumit Bose <sbose@redhat.com> |
Add ipa_hbac_search_base config option |
39b0adeaaf2429c7cbad045f7f8a79d51d02bee5 |
|
13-Oct-2010 |
Jan Zeleny <jzeleny@redhat.com> |
Man pages should mention supported providers
Each back end can support id, auth or access provider, but each
back end supports different subset of these. Man pages should
describe which providers are supported by each back end.
Ticket: #615 |
48a038d077ed2de18a5211e010c18ab680107293 |
|
16-May-2010 |
Stephen Gallagher <sgallagh@redhat.com> |
Add dynamic DNS updates to FreeIPA
This adds two new options:
ipa_dyndns_update: Boolean value to select whether this client
should automatically update its IP address in FreeIPA DNS.
ipa_dyndns_iface: Choose an interface manually to use for
updating dynamic DNS. Default is to use the interface associated
with the LDAP connection to FreeIPA.
This patch supports A and AAAA records. It relies on the presence
of the nsupdate tool from the bind-utils package to perform the
actual update step. The location of this utility is set at build
time, but its availability is determined at runtime (so clients
that do not require dynamic update capability do not need to meet
this dependency). |
57614e56dd272db0f71abc442b1515d79fd16169 |
|
07-May-2010 |
Stephen Gallagher <sgallagh@redhat.com> |
Revert "Add dynamic DNS updates to FreeIPA"
This reverts commit 973b7c27c0b294b8b2f120296f64c6a3a36e44b7.
While this patch applied cleanly, it was uncompilable. Reverting
until it can be properly merged. |
973b7c27c0b294b8b2f120296f64c6a3a36e44b7 |
|
07-May-2010 |
Stephen Gallagher <sgallagh@redhat.com> |
Add dynamic DNS updates to FreeIPA
This adds two new options:
ipa_dyndns_update: Boolean value to select whether this client
should automatically update its IP address in FreeIPA DNS.
ipa_dyndns_iface: Choose an interface manually to use for
updating dynamic DNS. Default is to use the interface associated
with the LDAP connection to FreeIPA.
This patch supports A and AAAA records. It relies on the presence
of the nsupdate tool from the bind-utils package to perform the
actual update step. The location of this utility is set at build
time, but its availability is determined at runtime (so clients
that do not require dynamic update capability do not need to meet
this dependency). |
66da80489c0114878043b40592c5f47d41eb0ffd |
|
07-May-2010 |
Jakub Hrozek <jhrozek@redhat.com> |
Use service discovery in backends
Integrate the failover improvements with our back ends. The DNS domain
used in the SRV query is always the SSSD domain name.
Please note that this patch changes the default value of ldap_uri from
"ldap://localhost" to "NULL" in order to use service discovery with no
server set. |
1c48b5a62f73234ed26bb20f0ab345ab61cda0ab |
|
18-Feb-2010 |
Stephen Gallagher <sgallagh@redhat.com> |
Rename server/ directory to src/
Also update BUILD.txt |